General functions for HTML manipulation.
"""
-
-_escape_map = {ord('&'): '&', ord('<'): '<', ord('>'): '>'}
-_escape_map_full = {ord('&'): '&', ord('<'): '<', ord('>'): '>',
- ord('"'): '"', ord('\''): '''}
-
# NB: this is a candidate for a bytes/string polymorphic interface
def escape(s, quote=True):
characters, both double quote (") and single quote (') characters are also
translated.
"""
+ s = s.replace("&", "&") # Must be done first!
+ s = s.replace("<", "<")
+ s = s.replace(">", ">")
if quote:
- return s.translate(_escape_map_full)
- return s.translate(_escape_map)
+ s = s.replace('"', """)
+ s = s.replace('\'', "'")
+ return s